#general
1 messages Β· Page 456 of 1
you talking about usb hub?
oh what GPU and CPU are you lokking for?
Advantage of a desktop is you can always upgrade it later.
Oh yeah that would be good.
That looks good as.
What is the best text channel to ask help about THM rooms, etc.?
just come to Iraq
pcpartpicker?
if u buy secondhand u can get a good machine
what is it you want to do with ur machine?
running vms probably
any games you really want to play?
If you're not too desperate, you could save up a bit and build a pretty good machine
714 euros can get u a pretty good machine but more money is always better ofcourse
need to verify
woohoo
VMs yeah. Don't do much gaming these days but probably will.
Hoping I can get something half decent for 800-1000
Idea. If I first learn C and start to hate it, when I switch to an actual language I will like it more than if I would've started with it
C++
If someone learns one programming language, does it become easier to learn others?
i hear from people that it becomes easier
but im not sure
i can barely code hello world
echo "hello world" π
C what I did there?
Idek what the C languages look like
C C# C++
python is always a good place to start learning to code
atleast thats what ive been told
you should try Malbolge
its a good language
Is it actually?
It also depends a little on what you intend to do:
Python: Great for AI, Machine Learning, automation, and general-purpose tasks.
C++: Preferred for game development due to performance and low-level control. C++ is also an extention on the "C" language. so c++ is Object oriented whilce C is procedural.
C#: Ideal for Windows apps and works well with the .NET framework.
so do some reasearch araound the language can be a good idea, since like python have lots of algorithms and so on for ai and ml that other languages might not have and so on.
I didn't even grab any coffee today 
Anyone gonna buy monster hunter wilds when it drops
Chug raw caffeine
@boreal scarab π
What donβt you like
Because if I do buy it this would be my first monster hunter game
can anyone DM me for some Snort Notes
don't preorder, wait a week after release to see the community response
What does it do
WiFis the duck
It quacks like a duck in wifi.
It's a keystroke injector like the RubberDucky but you connect to its WiFi instead and it has a web interface where you can send remote keystrokes.
The rubber ducky is limited to what is saved in the microSD
Oo
You can probably build this for like... less than $5-10?
Might be a good little project
it is like rubberducky just have wifi
Thatβs cool
like OMg cabel from hak5
The OMg cable is scary cool
yea. got one. kinda scary indeed
Hoi
add .ssh folder into dotfiles for github is not so smart idea =/
I hate kusto
the what ?
kusto query language
oh... was thinking some anime thing =/ at last kusto sound anime alike
microsoft shitty sql
not it make even more sense why you hate it π
hello new, im ralex
query language made for logs in defender etc.
and i am currently doing red teaming but i want to know at this level can i play king of hills or not ?
and also have some basic doubt
koth can be played at any lvl... iirc
thanks @loud marlin
Gave +1 Rep to @loud marlin (current: #25 - 345)
Hello, so I am looking for the most amount of free or cheap cybersecurity or program/technology/ai related certificates to obtain. Any recommendations or good ones that I could go for..?
Thank you
I completely agree with you
also there is #koth. so jump there will be ok
what if i want to job then what skill i want for pentesting
internet is free π
well... pentest is big area. you have, as you say, red team and blue team, SOC... you go for what you like to do
which is how I got tryhackme, cisco, and Ine, and some others. I'm seeking help over here as well since this server is primarily focused on such subjects 
but i want to know i done with all course pre security to red teaming and i have badges and some basic project then compny can give me a job or not ?
there is certificats that are proof of what you know to do. for example OSCP is one nice.
i know it's nice but i can't afford that because it's very high price in my region
i am thinking about ceh i am bit confuse some where i see it's imp but somewhere it's waste of time
Hmm, don't think of it as certification = job, think of it as in order to get certified, you need to have that foundational knowledge at least, that's what helps you at job interviews and that what gets you job interview
test
It's perfectly fine to apply to blue team job with red team certifications
Hello everyone
Iβm new here
but i want to know which is cheaper as a student that can i afford and valuable
@past sparrow
Internet is free, github is free, portfolio is more or less free to make, if you cannot afford acredited certification examinations then you need to sell your skill otherwise
How does port forwarding work?
and what if i add any extra skill like bug hunting
Sure, if you have any verified bugs you have found, they can be included, though if you just say you have skill to bug hunt but haven't found any then this won't help you too much
dont they actually prefer both certs? like pentesting
Depends on the employer, certification just tells them that you are familiar with the stuff, in the job you still need to tackle more or less newer or unique stuff, you will be trained the nuances on the job
thanks @past sparrow
Gave +1 Rep to @past sparrow (current: #248 - 23)
@past sparrow do u work in cybersecurity or u also learning?
I work
Almost 3 years, so I'm quite a newbie
what role
ok ok, guess you work as a blue team then like analyst or smth
yeah, currently im a sophmore uni comp sci (concentration cybersecurity) major.
I do CCDC (blue team w/ competitions) just started this year.
How likely am I to get an internship if I have CCDC experience and constructing my own malware as personal projects.
I dont got any certs
SOC L2
i wanna start red team from the start but i figure its better to start small and work the way up to get all the fundamentals of other fields
I will be honest, CCDC tells me nothing, its quite unknown thing to my region, malwares could be an interesting interview talking point though
start blue team
do not go to CEH. you learn as much you can, and when found some job then you go for OSCP or so
Our school is sponsered by fortune 100 company and we might go to regionals (but im prob wont make that specific team)
Junior pentesters are a thing, so not necessarily a need to start from blue side
Some hire straight from highschool if they have knack for it
Though if possible, I do recommend attending events like that if possible, any experience is better than no experience
yeye ik but i mean i wanna have a very wide understanding of everything before i do pentest as a job. like work in other fields, example analyst or engineer. U know i wanna be the best penterster:D
I do CCDC events, just not the main one since only 8 people can qualify per school.
The best uh, start learning clouds
Creating a blog and having a github, is also a good way to advertise your skills
Yeah, I need to add a blog section to my website ngl. I can just summarize what I learn and current events
yeh i will after i finnish studying networking. after that cloud
I am having so much fun with cloud π¬
nΓ₯gon svensk hΓ€r?
but people saying thm is only good for beginners, heard its not so good for advanced
I dare not to criticize it on its platform community
i dont ci'riticize
just saying what ppl told me
idk if its true tho, i haven't completed full course yet
thm is awesome, I use both thm and htb. The range is great from beginner to advanced
π€· It has its perks and missings, but I guess it also depends on stages where you are at learning
but advanced people use it most for koth right?
For me personally, the question-answer doesn't work very well, especially because I want to be wrong before I get it right
If I am right immedietly, then I forget it very fast, "no need to learn what I already know"
alr
I tend to get over this by making detailed notes. I don't rely on the QA to drill home the knowledge
I prefer my literature based approach, where I highlight and make my own notes, and then in practice trial and error, I don't like the idea of assessment, which QA usually leaves me with
As the almighty scrubz would say: A hacker is only as good as their notes
I really should practice going back to notes, I don't, I archive them and never visit them again
get certification and slowly start learning for next one
How does port forwarding work?
You essentially tell your router to forward requests that go to a certain port to a IP address within your local network.
To explain it in a very short manner.
how many users have been on this platform?
3579572
A - B - C
A tells B that he has web server on port 1234
B tells C that he has web server on port 80
and then B directs traffic from C that come to 80 to A on port 1234
modern routers let you configure it quite easily
So you redirect port 80 stuff to port 1234?
For example yeah
thought they have 100m user
So this is how web servers show u content?
Naaa.
Depends on the network setup.
is it actually the biggest hacking platform?
whats the usual case
HTB is large as well
I could not tell you.
HackerOne too
or how i should describe it just making sure my infos right for my linkdin post
ik but whos big
HackerOne, HTB, THM, etc.
great question
ima stick with "one of top platforms"
Use both THm and HTB ngl
iam using both but THM got alot of memories
Leveled up in the middle of the conversation lol
who id talk to if i wanna host a confrence and invite THM as a booth or a sponser? im studying in the best uni in MENA region
Honestly, I don't know, I have never set up multiple companies' network
@sick lance
Usual case these days is buy cloud and they do things for you
Depends on the architect and what they think is the best practice
oh ok ty
Gave +1 Rep to @past sparrow (current: #242 - 24)
oh yeah it updated my THM level mid convo π
I personally would use port forwarding in a situation where I am hosting a local server on my computer and want friend to join my game, so I port forward server traffic from my router to my computer
oh interesting ok
i love this platform from the bottom of my heart
Since all your personal servers are in internal network, router doesn't know they are open, so in order to open that path externally, you need to tell router what door it comes in and what door it goes to
literally the best thing to ever exist
if i had this platform in 2008 i wouldve became #1 on MENA region with everything related to cybersec as ive been coding since 2008 and now im 21
@mossy river thnx yall
Ya?
Scrubz while ur here? Is there a channel to ask for like study guides or recommendations etc or can that be done here?
In here is fine π
Alright!
You'd need email support. π
Im starting with SC-200 and the Microsoft learning path is just really boring. Are there any others that might prove useful?
What will I do after the tryhackme roadmap is finished?
There is over 800 rooms on THM, with at least 2 rooms released weekly, you won't be finished anytime soon π
pat yourself on the back for a job well done π
Been chipping away at the rooms for round 9mths, only 670 or so more rooms to get done
Someone take a sample of 100 rooms, put into average of length, add average of 50%, put it into speed, get average completion rate, calculate how long it would take to complete all current room, add average of 2 rooms per week assuming average time of work per week of the average completion rate, and find out how many days it would take to realistically complete all
You'd need more than one data set imo
One person can take 30 min(s) to complete a room,
One person can take 90 min(s) to complete the same room.
50% falls in the middle so good enough
how do you share internet via WiFi / WLAN ?
Share it with what?
Like lets say, there are two devices connected to a router, and the router doesn't have internet access but one of the connected devices does, via a different network. how do you share it to the other device ?
Depending on the device, you could hotspot it
thats an option but its not possible in my case.
What device do you have?
enable ip forwarding on the device and set a route on the router to use the device as a gateway
a raspberry pi that can only connect to 2.4 GHz WiFi. It can neither connect to my home router nor my PC hotspot since they only fire 5 Ghz networks.
hmmm I'm gonna look into this. Thanks !
Gave +1 Rep to @potent escarp (current: #913 - 4)
guys
You can't change the band?
im having a problem starting the attackbox
No worries sister.
WHAT
Nope, it only shows network name and password in my case.
he said "NO WORRIES SISTER."
hes tripping
it litrelly says 6'3/m/27 in my bio
is it possible that I can change the gateway in the raspberry pi itself ? Like set a different gateway than the router ?
Do you guys write when you study or you take notes on your PC/Laptop?
Yup
while studying I write, but after a study session, I try typing notes on my PC by recalling what I learned.
I take notes during lessons, sometimes I will use an AI to record the voice and it will take notes based on that.
But with a pen on paper?
Not digital
?
I also think that writing is better for remembering
I have a small pad for those quick notes.
Usually just bullet points for topics I need to research later.
I use pen on paper... my brain is very passive when typing
I agree
That works for topics that you are in touch I guess
Once I only wrote and once I tried only typing
How I record my notes depends on the lesson.
if I use slides, I'll import them to Firefox, and draw notes on with my graphics tablet during the lesson
hi guyz
i am planning on starting a server
So i need basics of networking? Anyone know where i can learn it from?
there are a few rooms about networking on THM, you can watch Professor Messer videos on yt about net+ and David Bombal content about CCNA
what kind of server ?
web hosting
for own things or ?
training some ML n algos on it just for practice
yeah for own things
well... why not just buy/rent some?
who gonn pay when i have a machine in my room
fair indeed. then you going for long ride if wish make it online and so on
u broke that also ?
I pwead da fifs
exactly
what did he break this time?
yes π
damn
Thanks for sharing your experience with me everyone!
Damn. Not seen you in ages, Ems
the no meowing π
i am everywhere yet nowhere
Just arching around the world
You must be knackered
i think it's ok...
very
also got a new tattoo yesterday lol
but got a 6am flight friday
Bella was getting inked yesterday too. Must be contegious
How early do you need to be there for a 6am take-off?
Well, the website - Tryhackme.com - has a tonne of free content on there.
yeah thnx brooo
the bus timing makes it hard in the morning
later in the day it runs every 20m
that time, its only every 45
Yeeeaaahhh. Although you have an interesting pitch, I'll have to say.. I'm out. Good luck with the other Sharks/dragons
takes a while to clear customs and security to gotta be early
what plane is it?
X-71 π
E175 -> 737 Max 8
LMAO that's brilliant 
i got one book of fly thing
Ahh. so those red ribbons are how planes stay up. It all makes sense now
same as how cows fly
Gotta be careful not to get a .... pat on the head π
tru tru
Someone tried to bribe me with one dollar
what is the cuman doing? π
Seems like you took it 
Your better then me. I woulda took it
β€οΈ
what does the neofetch look like
neofetch is out of game... so to say... fastfetch is ok replace for it
What is the point of neofrtch
to be cool π
Does it give you street credit in the hacking field
Do any of yall know if comptia A+ is graded on marks secured or by questions fully correct?
can someone walk me through the last stage of MonitorsThree please?
i found a .js exploit but im unfamiliar with .js execution
yes...
#room-help for thm
time to daily drive this on my uni laptop
heya, wassup gang
Yo
i feel like im not organising my notes as well as i could be, but idk what would be an efficient tree structure(can link to notes, using obsidian)
it's your funeral
@restive thorn Hey
look at this mess lol
@karmic geyser hey
yo
Btw if you want less spam below your question, post it in #infosec-general 
I'm not a pro with obisidian so unfortunately I cant answer
might be a good shout yeah, thanks
well its lacking structure is all
my man
My bad, it's not THM, can you please use HTB's own discord server please.
sorry scrubz π€£ ππ
i think maybe keeping it general and simple does indeed work
let me try and organize it that way
i took inspiration from @grizzled crystal
i was thinking of dming her yeah, shes a notetaking queen
hello guys , im running an nmap scan from a server in the cloud to scan my ip for open ports , im using wireshark on my pc but i don't see any scan packet , why is that?
For the showing part (i.e as cheatsheets, and stuff to refernec from)
- Tools -> every file is a command, eg
hashcat.md,find.md - Terminology -> Concepts like
CIA Triage,Zero Trust - Techniques -> Specific techniques like
Cracking WPA2 handshakes
For the understanding part (i.e the 802.11 standards for wifi hacking)
- Theory -> Theory which explains how the technology works, why its vulnerable etc
thanks alot man, appreciate it
Gave +1 Rep to @shut hawk (current: #14 - 569)
anyone here watch house md?
Thanks, also please refrain from posting in multiple channels π
Gave +1 Rep to @restive thorn (current: #491 - 10)
yeah I'm gonna say that sounds pretty sketchy
looks ok to me... idk
You could send me a DM so I could add you to my server so you could see my previous hack*recovery
maaan i hate it when people sound suspicious but don't seem suspicious
i don't like ppl =/
Seems you donβt know anything about the cyber world that why
How do you do it?
You can tell me here.
sharing is caring
they're totally sus, but I'll ask that you please stay out of this discussion, thanks
Gave +1 Rep to @gusty river (current: #2243 - 1)

using ls -alh is no hacking =/
Unless your audience is hollywood
Lovely, love how AWS sends every possible mail to my mailbox, but when I go over planned budget, they send that notification to spam
right then, I'm going to assume they left now.
Woah!
ello ello poki
doing great... switch to arch and i going insane a bit... but ok π
you ? done with vacation ?
Omg arch.. Yeah, that'll do it. You using it as a main OS?
It's fun to configure hehe
Yep I'm doing okay! I've been setting up proxmox on a hetzner server myself, going insane doing that. I think I finally got a working network configuration going today, which is cool. Ipv6 is a pain to set up
yea... as main now. play with hyprland desktop...
https://discordapp.com/channels/521382216299839518/680459914828972076/1290379133104291933
Oooh very cool
thanks... atm working on dotfiles... it is up just making changes and so
Gave +1 Rep to @grizzled crystal (current: #131 - 56)
I need to get into learning a good window manager. I love tmux, just never got around to learning something like i3. I also need to learn ansible probably
Cool!! Yeah I should do that
ansible is great
One day
It seems very convenient
it is
then try hyprland. i used ml4w github script. like pre-set configs and then just play with it
I also want to learn emacs π i saw a video of someone using it and I really want to scratch that learning itch
I'll try it, thanks! Do you like it more than i3?
Gave +1 Rep to @loud marlin (current: #25 - 346)
meep moops time for early sleep sloops to the beep boops because of screwed up sleep because something made shadow wake up at 02:30
this is first thing i use. so far never try any of this tilling manager
i can DM you github if wish check...
Ahh cool cool. I tried i3 for like 5 minutes in total so I'm basically the same
No need i found it
shocked pickachu face
look for ML4W dotfiles on github. but in general hyprland website
Hello!!
hi!
Ever finish the magnus archives? Haha
never actually did no
You got pretty far though I remember
could def get back into it on my daily commute to work and back
Another victim falls
How've you been?
Are you still studying? It's been awhile
Peter Capaldi is in S7 of Black Mirror
cant complain for sure, life has been on the upside for a few months
Is black mirror good
doing my last internship and thesis now
100%
Black mirror is good
Ahh cool, must be busy. Good luck with everything
Glad to hear it :)
thanks so much, its a shift for sure but its fun
looking into the integration of a red team within the orginization
That sounds great
so pretty dope stuff, although not as technical
Still important
Jr red teamer? That sounds tough
would lack a huge amount of skillset, but well see
It's not really a thing as far as I'm aware... Although it depends on the org i suppose
w8... is s7 out ?
oh
Jr Red Teamer is a bit like Jr Surgeon. Like, you need a lot of practical exp to get into that type of work (red teaming)
You could probably do jr pentester
Some returning stars.
Why is black mirror in my star trek
they dont yet offer pentesting, and idk if they will, so not sure
On that note, do you know if something like jr pentester could be done at the same time as college, assuming you manage to get employed?
Oh hell naw, not another star trek fantasy one
If you can handle the load, I don't see why not
USS Callister?
Part 2
(logical step in my head would of course to start with that but if its a service you can probably start everywhere)
Hardly know her
Yeah definitely look into it
@lament tendon is gonna do his maters degree while (probably) also getting a pentesting job, so yes, its possible
Heya Aquilo haven't seen ya in a while
It's not easy, but it's not impossible.
I too am in this discord
In my case imma get the pentesting HTB academy certificate then imma try to land a Jr pentester role
All while doing college
Sometimes I wonder if i hate myself
Eh, I almost done it
this vexes me
Hi hi! I've just been lurking haha
Except I couldn't move to be closer.
Yes who are you? How strange
same for the most part.
Did you get your lightweight mouse?
More mouse bites
the when
As long as you know where stuff is that's all that matters
My notes are deliberately very organised because I have 1 braincell and 0 capacity for memory
So i forget stuff but I also forget where I wrote it down
Only have my phone so Iβm going to use notepad to try anyway
what app is that for notes?
I still like obsidan but I wouldnt mind trying something else
the backlinks are nice but being able to have an organized section like that could be nice
I mean it doesnt look bad to me
what do the actual note pages look like?
mm I see I See
You should try trillium
Join the trillium cult
Oh yeah I forgot about that... π
Yeah it never ends. My activity is probably going to be extremely sporadic until November or later. Lots of stuff happening irl atm that I'm trying to deal with
The new Breakme room got me to cave in... had to lookup the walkthrough D:
Don't know which gave me more of a headache the room or walkthrough. Lol
anyone ever contacted telegram and got a response?
ANOTHER KCD ENJOYER WOOOH!
Do aliens exist?
:8ball: Signs point to yes
π³π³π³
I wonder where they got this idea of what the aliens look like if we never actually seen a alien
was playing around with stable diffusion and wanted logo inspiration for something and it came up with this, love it
wasn't quite the vibe for what I wanted but it made me happy haha
Quick question guys, can you do the full learning path of the "Introduction to Cyber Security" for free?
I got to the "Operating System Security" part and it sends me to the premium thing
Well some stuff needs the subscription
Is there any learning path thats easy that you can complete for free?
Thatβs a good question
I donβt really keep track of whatβs free or not but there are plenty of other rooms that are free
Any good rooms for starters that you recommend?
test
hello
99v8ZcGUThsLHTuBrdGWANAw9xY1EMWvLD77yfKLcR39bfEfbK66j9Ehab1a3jsCgB7Eob96DQMKwFBBLQQXMx1nXb57ZeBQFer7Xoba
please can someone crack or tell me the type of encoded text this is?
Got it, thank you so much!
in this field researching is key
base58 ---> base64 ---->base32
Thanks alot @fervent meteor
Gave +1 Rep to @fervent meteor (current: #61 - 128)
What was this for?
π
Hello community. Am new here and i dont know anything about hacking but i am interested and want to get started so how am i getting started?
And after?
I want to do that
Natures ChatGPT
βNature make me a programβ βon it bossβ
Well it's coding in its own lang
bait
https://killercoda.com/ free k8s&DevOps&Docker courses and free playground, ooooooh Booiiii
as far as steam download speeds go, really can't complain
God damn, yep
I thought I was sitting pretty cool at 85 Mbps downloads from Steam
Steam is consistently the fastest download speed I ever experience on any given day lol
Could any one explain me about kllrcoda
But we may have some 100 Mbps bottlenecks in our network that I'm not aware of. That was mostly my SO, despite me setting up the network every place I've been before. The perils of living with someone else who works in IT lol
If you don't know what DevOps, Docker or Kubernates are, stick to TryHackMe and that will actually teach you the fundimentals. It sounds like that site is geared much more for people who are at least familiar with DevOps
Although I guess I somewhat counteract this with the homelab server that I administrate and he just uses lol
Bro could you tell about kali Linux what I have to learn in kali Linux and which way I can learn about it
It's a PowerEdge T430, it's massively overpowered for most of our needs beyond video encoding which we use heavily lol. That I can't complain about lol...
I guess I say that until I actually look at how much resources we're using in vSphere lol
You can learn about Linux more generally via TryHackMe. You can actively use Kali Linux yourself to do TryHackMe either in your own VM or with a paid subscription which gives you Kali as an option to replace the default TryHackMe Linux "AttackBox"
Probably the easiest ways to get started there, but I'd recommend general Linux knowledge first, you need the basics
Thanks bro
np
I will say that the Linux box option on THM is deprecated
Unless they changed their minds
Hmm? The regular attackbox or the Kali? Or do you just mean THM's Kali is out of date?
It never went away as an option
I think I remember it being out of date for a while
If that's the case, should still be enough to get someone like them started, but sure, your own VM or similar solution will always be better
Yeah fair enough
iirc their "AttackBox" Kali was out of date even when I was doing a bulk of the rooms a couple years back. I'm guessing it probably hasn't progressed since then, which I can't blame them on much. Kinda just an "extra"
Bro are you saying that kali is old. So , can I use black arch or parrot os . If you have any other idea pls tell bro . I am new in this field
No, we're saying the in-browser Kali option on TryHackMe is not updated
Kali that you download today and run on your own is up to date
Ok thanks
Good morning everybody πΆβπ«οΈ
I just died in a boss battle after 30 min during the final phase.
Condolence
I beat the boss nowe
U guys a hacker?
This is an ethical hacking discord, yes
Not everyone does hacking here though
whatchu need bb
sus
@molten sky π€£
Mr robot is good but I feel they show less and less actual hacking as it goes on
Season 1 they're hacking constantly
Season 2 was a real slog when Elliott was doing his offline thing
I haven't watched season 4 tho yet so maybe that reverses the trend
Spring now yeah
Summer starts in December
the same as Argentina π
What's up
?
I was too much in a hurry I forgot to properly place the question mark.
Don't wanna throw an error
Failed to compile
@blazing granite are you in Argentina?
I hear it's beautiful this time of year.
Wow, I have typed a couple of lines and haven't offended anyone.
Must be some kind of a record.
That's a good start.
There's no reason to add unnecessary complexity, so the first one.
I like it complex
It gives a spice to life.
If I say simple people don't like it complex, I would probably get banned
Therefore I didn't say it.
Actually it's complex
but it's still funny.
Lol
my shoulder hurts still
'still' ?
yeah, over the last 2 days 
tf did you do lmao
got a tattoo
ah that's actually reasonable i suppose
like i know for a fact you weren't getting a typers shoulder or some nonsense like that
what is it tho
some good detail
how long that'd take em?
that sounds pretty in line
next one takes 3 days
Wow, shade work is outstanding
I can hack ur wifi using html π
For real?
Hi I'm new here happy to be here
real heckers use CSS to heck
\s
Those aren't coding languages
they were being sarcastic is all
yeah, he wins in black and grey and realisme competitions
good haha
idk when this min maxing thing became a thing but my god
also taxes aren't difficult as an individual π€·ββοΈ
well and it kinda works on a website that i use everyday π
and they dont have a bounty program π¦
nvm
taxes are stright forward but deductions are not. evything has a clause that needs some thinking
and money matters aint my strength
Don't attack sites without permission. It's illegal.
im sorry, it's my first time
not gonna do it again
β€οΈ
if true ---- html injection isn't normally rewardable anyhow
check out bugcrowd and hackerone if you want easy access to bounty and disclosure programs
good place to start as long as you follow the written scope
yea i need something more evil like XSS but im still learning javascript so ill just keep learning till im ready
for hunting
legally
it's true, they're using innerHTML not textContent, that's why something like this works <h1> hello world </h1> | <h6> hello world </h6>
how dumb
anyway
im learning DOM
rn
yeah that by itself wouldn't be rewardable normally ---- you'd need to prove a business impact of some kind
however, if they aren't filtering tags properly, it'd be a path worth exploring (on allowed targets)
business impact is everything
they do filter tags but i guess burp encoding can bypass that or something, my friend told me about this but no idea what is burp and why should i care
HTML injection, if it stops short of XSS, tends to be useful as a phishing or malicious link angle tbh
Are Intel i3 processors any good?
Yes you should learn burp and leaen about encoding, but encoding probably won't do much
prob something like this (change ">" to some kind of ("&mnfwefwefyh43")
They process
I was in the process of elaborating on that but then I saw NinjaJc01 is typing and was like nah probably too much for a new user or something π
depends
I'd hope so?
if they aren't filtering tags properly then it's a very worthwhile thing to investigate normally
Are they quick?
depends
i was using i3 10100 for programming and playing valo, cs2, rdr2
working fine
i'll
Not the quickest on offer. They're at the low end for Intel
thanks BROs
Yeah I've got i5 atm in my laptop but looking for when I build a pc
React with Dompurify are already existed this days but most websites don't use it .. what on earth
thm has a whole module for burp suite --- quite well put together as well. highly recommend it
Hi everyone. Question, in which room in this channel can I dicuss and get help with malware? Thanks.
burp is one of the only "conventional" things I use non stop
but productivity, you wanna hear about my next tattoo?
unfortunately that is a no go
#771818902342074388 or whatever only
no idea what is dompurify π
ill look into it
thm logo across the back
wdym "for a comp"?
I'm not writing it, I'm trying to sanitize a pc
ah if it's remediation that's probably fine
normally when a green-leaf-user pops in like ay how do the malwares it's the opposite
I'd argue if you're using both, you're doing something wrong
https://www.stackhawk.com/blog/react-xss-guide-examples-and-prevention/
React understands the concept of safe sinks and makes the sinks safe. Sanitizing is a 2010s tactic. Separation of code and data is the proper robust way to fix injection flaws
gotcha. I should have realized it's a loaded topic, and clarified from the start. I'm trying to clean an infected machine.
yeah if you have specific Qs there's not really a specific channel or anything π€·ββοΈ if you're looking for general advice, it very much depends on the situation at hand (what's at stake, what type of malware, technical ability, etc)
ideally, a compromised endpoint is just nuke and paved
but clearly not always the easiest irl
My technical ability is basically non-existent. I might need to hire someone and I'm trying to get a scope on the problem.
I am a canvas for my artist at a tattoo competition
do you know what it is / what's happening
share ur mess
oooooo one of those ---- is there a known criteria/theme/etc yet or
realisme, he already designed it
A malicious browser cookie gets loaded when visiting or logging into specific websites. It interferes with use of the pc's wifi adapter, making connecting to the internet via wifi impossible. Closing the browser doesn't help, and neither does rebooting the computer. The only thing that works is clearing the browser cookies. But this means being forced to log out of said websites.
ok thanks
Gave +1 Rep to @naive violet (current: #2 - 2188)
The two can't be related
They absolutely are. I've conducted numerous test, and tried it on 3 different machines. One of them I even formatted the HDD and reinstalled the OS. Same thing occurred.
If a site is, as you claim, setting a "malicious cookie" then it's malicious.
But I don't think that's what's happening at all.
This isn't a technical support forum outside of direct help with tryhackme, so I'm providing guidance as an IT and security professional.
I've been told by another hacker that it coud be talking to a process on the pc itself.
The same hacker recommended me this discord server
A lot of people who call themselves hackers... Aren't.
Download malwarebytes and do a scan.
It's undetected by anti-malware software. I've already spent $1000 trying to solve this problem. That's why I'm now seeking professional help
If you've tried it over a bunch of devices, either you're repeatedly installing this "malware" or there isn't any. That's the simple answer.
I think I need to speak to someone else. This is obviously an area outside of your knowledge base.
There's no need to be rude, my advice is based in actual reality
I have a question.
If we are digital nomads,
Are we also relationship nomads?
Idk
Woooow
So is mine. And I've already spent a lot of money on this. And you're being dismissive.
You spent 1k and now seeking professional help!?
Forgive me for believing I could solve the problem on my own
What did you spend 1k on?
@urban grail you cannot, that's why there are specialists.
This is the sunk cost fallacy.
...You seriously can.
For example, I am a specialist at wasting my time.
And drinking too Munch.
Lol
I didn't know that until I discovered I wasn't having hardware issues. Remember, anti-malware software was detecting nothing
i created a simple keylogger but anti-malware software can't detect it is anti-malware software a joke?
What you don't was not unethical, but illegal
Done*
The average person does not justify bespoke malware development.
So, you think you've infected with malware, via bad cookies which is disabling your WiFi connection?
yes yes i do it for educational only
i use python and make it into exe
Ok, that immediately flags anyway
I think the cookies are talking to an invisible process on my pc, which interferes with my wifi connection when triggered by the cookie
But let's not discuss malware dev here
What would a malicious hacker gain from turning off your wifi?
the lolz ofc
It isn't, as much as so many people wish, the late 90s anymore
late 90s?
malware used to be fun
now it's just oh no where'd my life savings go
U are making malware?
Banana split, expresso
https://youtube.com/shorts/dXAQw9hjtJY?si=mLkp1sg41rQHWCf_
Making people unable to connect to the internet could be of benefit to some
Ohhh
No, and we don't discuss that outside of the advanced channels.
Oh? Please elaborate why you'd be targetted in this way?
@torpid furnace No.
Money
short and sweet lol
I thought we were here to discuss technical issues?
Without a ransom note?
They have all your passwords cookies and remote access to ur pc
Yep. Motive is part of that.
There's no malware here
And credit cards if heβs uses any
Access your pc, but switching off your ability to connect to the internet?
Not necessarily. It's allegedly turning off wifi. So.... No remote access.
That'd be the world's worst hacker
Ddos attack then ππ
Without WiFi?
Not internet, wifi.
No, you just don't know how to help. We've exhausted your knowledge base. But thanks anyway
Gave +1 Rep to @naive violet (current: #2 - 2189)
Can I ask.
:mute: grifter1979#0 has been muted.
Nope.
i guess if we're being semantic it could theoretically be remaining connected but denying communication to anything but itself -- sorta like how you'd isolate an ep via your edr's agent -- but yeah that's not very practical
IPoAC maybe π
What makes you important enough for hackers to turn off your ability to access the internet, and not steal your data (which the greater majority of malware does) ?
IPoAC is still faster than copper once you hit a certain extremely high data rate π€·ββοΈ
Ah, but it's wifi failing. Not internet.
People just do it for fun
π€£
Anyway here's a really nice unrelated article about IIS and .NET hacking that y'all should read
https://zeroed.tech/blog/viewstate-the-unpatchable-iis-forever-day-being-actively-exploited/
hm. i guess you could make it appear as if wifi itself was failing, but that'd be a very weird and unusual extra step to take. a good bit of extra work for absolutely zero benefit
This is something that's easy to reality check.
There's no malware here.
Thereβs a malware called Pysilon and these kids were ratting ppl and spending their money when I finally joined there server they were able to info steal, break windows, bsod take videos and 24/7 microphone
All info goes through discord bot
Info steal. That's the impact.
That's not for "fun". That's impact.
Again, let's not discuss malware outside the correct channels
And let's move forward with our lives
move forward? impossible
regression is the way forward
who are you going to see?
really? info stealing without clicking a link
By opening a file
@torpid furnace @forest canyon Stop. This is your last chance before a mute.
lineup hasn't been released yet, pre-sale is opening in 40 minutes
turning off your wifi and phone service( assuming your phone only uses ip phone service and have no other coverage ) could be used to abuse your accounts if they already got your creds but need you to not be able to warn the people you work for or friends and family
yes this would be a decently rare senario
i've googled boiler room but i genuinely don't think i have the right thing
but could be out there
DJ sets
huh. i guess it is the right thing
Often big big big names
interesting
sowry im behave now
wish I could go to london for a boiler room, then I might have a chance to see fred again π
the boiler room is good for winter, it's dead hot during summer π π π
this would be an interesting concept. idk if it's go so far as to say "not able to warn" but moreso unable to kill sessions or change info
yeah that would also apply to shadows senario
sale opens today, the event is in december
still it would be decently niche in most situations
i'd imagine that would be pretty highly targeted in most cases with most opting to remain undetected rather than in your face
yeah
Again, please stop, let's move on
@chilly veldt you spelled reaslism as realisme the same way twice and i thought it was a typo the first time
is that just how y'all spell it there
yup
huh. TIL. didn't realize there were places that had that spelling
realism vs realisme
took me a second the very first time reading it (albeit after drinking) like wtf is a real_is_me
realisme, is maybe me that realise π
Wondering how good a pc would be with everything included in $2000. Monitor as well. Keyboard mouse and headset not.
only one more drink it is
one for the road π I'm join you with g&t π
as long as the desk isn't included then pretty good tbh, as long as you aren't buying overpriced nonsense like a 700 display for no reason
Nah I wanna budget. Make it efficient.
mine cost me less than that idk how many years ago and is only now becoming unable to max things out
mostly due to vram limitations
You can upgrade tho ay
absolutely --- but point being 2k is quite a bit to play with
if I were building today tho, I wouldn't build a normal tower -- it'd be another rack in the basement away from my desk
screw having a space heater in the same room as you 24x7
vroom vroom
How was it?
torquey but also not so powerful where you're still only in second gear on the highway
buying back in today, i genuinely don't think i would go up in power --- i quite enjoyed that spot. was able to stretch it's legs on normal roads without becoming the next gixxxerbrah or pavement paint
could still get the front up in third pretty easily with that
oh man it was comfy too --- taking the ninja out I felt like shit coming back --- the mt after a longer ride I would be near-deaf and might have some ear ringing from buffetting but my back and body felt so much better
@urban grail
I hope you're not sending the file to our community members.
There is no file, Scrubz. The only thing that's been documented so far is computer behavior.
The irony here is you're seeking professional help, but still asking in here when two people have told you what it isn't.
I've been speaking to people outside of this forum as well, and they say differently
Are they professionals?
Their credentials are the same as people here
random people in the internet credentials? π
So that will be a no.
Ninja is probably more qualified than all of them tbh
Anyway, I'm not interested in debating it. If that's all you want to do, then I will bid you adue
I'm just more curious on why you're breaking our rules.
Discussing malware infections is breaking the rules?
I don't intend to debate your "malware" as everything you've said goes against the majority of malware.
No, dm'ing members without asking.
they gave me their permission.
Anyway, with that said.
We can drop then subject.
It's already the Q4 of the year Stop waiting for the perfect moment to chase your dreams, create that moment today, Remember, small steps of every single day will lead to big, life-changing results. Youβve got everything it takes, now is the time to start and make it happen, you still have the last quarter of the year to make to achieve success. Like I also did! Let's go!!
Please stop posting across multiple channels.
π
@sick lance Hey buddy what's up can you delete the try hack me account that is linked to my profile I created a new one
Can you DM me the token and username of the account?
Sure
I'll leave you with this. There has always been malware designed to corrupt files, format HDD and/or damage systems. Why couldn't there be malware that harms telemetry? π€
Because 90% of Malware is intended on extraction of data.
They can't do that if all it does is turn your WiFi off.
I'm betting you've changed a setting on your laptop and you have no idea what you've done.
Yeah, after all the testing I've done, no way.
Are you a professional?
Have a good night scrubz
Have a good day π
my brain hurts
Yeah brain isn't hurting, it has exploded.
Why does this chat never fail to get weird at this time?
Because shadows dream scape is leaking Into chat
Guys, who will join me in a challenge because I'm bored?
yeah, brain explodes because I have to segment 286 servers into networks that makes it most optimal and secure
Guess you need at minimum class b netwoeks/16 then
vlans π
Yeah.... Was thinking subnets
don't worry, it's at /8 level π
That sounds fun
we are dealing with IP in class A and class B
what is /16/8 lol still learning about subnets
how many locked bits there are in the subnet mask
255.255.255.0 is equal to /24
Oh yeah
Each octet is 8 bits so should be easy with /8 and /16 too
255.0.0.0 == /8
255.255.0.0 == /16
Hey guys
IΒ΄m on my first learning path: Introduction to Cyber Security
Introduction to Offensive Security
Web Application Security
and whatever I type here: What do you need to access a web application?
is wrong
itΒ΄s just a browser, right?
When should I switch to HTB?
When you feel like you're ready
#room-help for THM support
Yeah man, thanks.
Gave +1 Rep to @sick lance (current: #1 - 2832)
Ideally, nobody but you can decide if you're ready to move on to other things/harder topics.
hi
hello
Understood, so basically if THM becomes smooth and easy then I should switch
henlo
i hope you all have a great day
you too
HTB looks confusing anyway
It has a lot of different difficulties lol
Idk bro, there's gotta be a reason everyone keeps recommending it
Like what?
Are there any insane rooms take take forever to work out?
how can i get my hacker role?
You need to verify
Yup
Yeah nope confusing hahaha, you done it?
Half of it
K2 is really a nice machine ngl
can any1 recommend good cybersec blogs?
Guys who can help me
not cool happend two times right before final exploit
In Subs room help
what room exactly?
aahh i see
give me a sec i look into that
Okay
@oblique ravine thank you
Gave +1 Rep to @oblique ravine (current: #2243 - 1)
